VDB
CVE-2005-2069
CVE-2005-2069
PUBLISHED
Reported by redhat · Published June 29, 2005
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | *, n/a, n/a |
Timeline
- Jun 29, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- x_refsource_CONFIRM
- GLSA-2005-07-13 vendor-advisoryx_refsource_GENTOO
- x_refsource_CONFIRM
- x_refsource_CONFIRM
- 14126 vdb-entryx_refsource_BID
- RHSA-2005:751 vendor-advisoryx_refsource_REDHAT
- ldap-tls-information-disclosure(21245) vdb-entryx_refsource_XF
- 17692 vdb-entryx_refsource_OSVDB
- x_refsource_MISC
- 20050704 pam_ldap/nss_ldap password leak in a master+slave+start_tls LDAP setup mailing-listx_refsource_FULLDISC
- x_refsource_MISC
- 17845 third-party-advisoryx_refsource_SECUNIA
- 14125 vdb-entryx_refsource_BID
- oval:org.mitre.oval:def:9445 vdb-entrysignaturex_refsource_OVAL
- x_refsource_MISC
- MDKSA-2005:121 vendor-advisoryx_refsource_MANDRIVA
- 21520 third-party-advisoryx_refsource_SECUNIA
- RHSA-2005:767 vendor-advisoryx_refsource_REDHAT
- 17233 third-party-advisoryx_refsource_SECUNIA
- USN-152-1 vendor-advisoryx_refsource_UBUNTU